Lucene search

K
cve[email protected]CVE-2009-1912
HistoryJun 04, 2009 - 4:30 p.m.

CVE-2009-1912

2009-06-0416:30:00
CWE-22
web.nvd.nist.gov
19
cve-2009-1912
directory traversal
webspell
remote attack
arbitrary execution
php
language cookie
security vulnerability

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.3 High

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.3%

Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a … (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.

Affected configurations

NVD
Node
webspellwebspellRange4.2.0e
OR
webspellwebspellMatch4.0
OR
webspellwebspellMatch4.0.2c
OR
webspellwebspellMatch4.1
OR
webspellwebspellMatch4.01.00
OR
webspellwebspellMatch4.1.1
OR
webspellwebspellMatch4.01.01
OR
webspellwebspellMatch4.01.02
OR
webspellwebspellMatch4.1.2
OR
webspellwebspellMatch4.2.0c
OR
webspellwebspellMatch4.2.0d

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.3 High

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.3%

Related for CVE-2009-1912